Set up checkout
Get a business account, card payments, an API key and a webhook endpoint ready before your first live payment.
Summary
Section titled “Summary”- Create a business account and verify it (KYB), in the dashboard.
- Apply for card payments under Checkout.
- Create an API key and a webhook endpoint under Developers.
- Check both with
GET /checkout/organizations/{orgId}/products.
publish: true create keeps the link as a draft with a publishError.-
Create a business account
Section titled “Create a business account”Sign in at business.avvio.xyz with your work email and a one-time code, and add a passkey if you like. Name your business and choose Create Business Account. This creates your organization, which holds the balance, links, API keys and team. Of the dashboard’s setup tasks, checkout needs Create account and Verify your account.
Verify the business
Section titled “Verify the business”Open Verify and complete business verification (KYB). It asks for the legal entity, its beneficial owners and one control person, the individual who runs the business. Card onboarding verifies exactly that person, so it cannot start until the application names one.
Status What it means Draft Not sent yet. Finish and submit it Under review With us. We email you when it is done Needs information We asked for something. The dashboard shows what, and a button to answer Approved Every organization-scoped route opens, including checkout Rejected Contact support Until then, checkout routes answer
403with “This organization must complete business verification before it can accept payments.” Our approval counts as verified, and so does the card processor reporting the business able to charge. Bank and stablecoin payments go live on approval; cards need step 2. -
Enable card payments
Section titled “Enable card payments”Open Checkout and choose Accept card payments. Anyone on your team can file the application. Cards are in pilot, so if you cannot have them yet, the panel says so in place of the button.
Cards are processed by Whop, which verifies the control person your KYB names. The consent screen lists what is shared: the business’s registered name, address, tax ID, structure and activity, and the control person’s name, date of birth, phone, home address, tax number, ID photos and selfie. Tick both boxes. If you are not the control person, you attest that you may consent for them. Consent is recorded once.
The card account opens in about a minute. If the ID photos and selfie on your verification were accepted, the identity check runs from them and nobody is contacted. Otherwise the page says what to fix, and the control person does a two-minute ID and selfie check on their phone. The dashboard shows the link to send them, and Whop emails the account owner too.
Switch Turns on when What it lets you do Card payments The card account is open Publish links with methods: [{ "kind": "card" }]; buyers pay by card, Apple Pay and Google PayWithdrawals The identity check passes Move card money to your bank from Checkout → Balance Card money waits in your card balance until withdrawals are on. Buyers see
WHOP*and your business name on their statement; edit the descriptor in the same panel.A card link published before this is done gets a
201but stays adraftwith apublishError(Accept a checkout payment). Finish onboarding, then callPOST /checkout/organizations/{orgId}/links/{linkId}/publish. Bank and crypto links skip this step. -
Create an API key and a webhook endpoint
Section titled “Create an API key and a webhook endpoint”Both live under Developers, which owners, admins and operators can open.
The API key
Section titled “The API key”Choose Create API key and fill in four fields:
Field Pick Name Where it will live ( orders-service), so a leaked key is traceablePermission Transact to create products and links. Read-only gets 403 INSUFFICIENT_on any write. Refunds need a separate scope (Refund a payment)SCOPE Expiry One year by default, two at most Allowed IP addresses Optional. Your servers’ egress addresses export AVVIO_API_KEY=avvio_…export AVVIO_ORG_ID=cmsx… # your organization id, a cuidexport AVVIO_BASE_URL=https://api.avvio.xyz/business/api/v1Use the opaque
cmsx…organization id shown on the same page, not anorg_-prefixed alias.The webhook endpoint
Section titled “The webhook endpoint”Open the Webhooks tab and choose Add endpoint:
- URL: https only. In the sandbox, use a public HTTPS tunnel such as cloudflared or ngrok.
- Events: payout types are pre-selected and checkout types are not. An
endpoint receives only the checkout events it names, so tick the
checkout_payment.*types you handle. - Signing secret: shown once, as
whsec_…. Store it beside the API key and verify with it (Receive and verify webhooks).
Endpoints are managed only in the dashboard; a key can list them read-only at
GET /organizations/{organizationId}/webhook-endpoints(Webhooks). -
Check the setup
Section titled “Check the setup”Make one read before you write anything:
curl -s "$AVVIO_BASE_URL/checkout/organizations/$AVVIO_ORG_ID/products" \-H "x-api-key: $AVVIO_API_KEY"A new organization gets
[]. A403with the verification message means step 1 is not finished; a401means the key is wrong or revoked.@avvio/paymentscovers most of partner-checkout.openapi.yaml: use 0.8.0 or newer for refunds and 0.7.0 or newer forupdateCheckoutLink. Publishing a draft, deleting a draft, and reading, updating or archiving a product have no SDK method yet, so call those over HTTP. From an API key, everyPOST,PATCHandDELETEneeds anIdempotency-Key.Next, accept a checkout payment.
Was this page helpful?